AWS Certified Developer – Associate (DVA-C02)DeploymentMedium

A developer is configuring an AWS CodeBuild project to build a containerized application. The build process requires pulling a base image from a private Amazon ECR repository and then pushing the final built image to another ECR repository. What IAM permissions are essential for the CodeBuild service role to successfully perform these actions?

  1. Acodebuild:StartBuild, codebuild:StopBuild, codebuild:BatchGetBuilds
  2. Bs3:GetObject, s3:PutObject, s3:ListBucket
  3. Cecr:GetDownloadUrlForLayer, ecr:BatchGetImage, ecr:BatchCheckLayerAvailability, ecr:InitiateLayerUpload, ecr:UploadLayerPart, ecr:CompleteLayerUpload, ecr:PutImage
  4. Decr:DescribeRepositories, ecr:ListImages, ecr:GetAuthorizationToken
Show answer & explanation

Correct answer: C. ecr:GetDownloadUrlForLayer, ecr:BatchGetImage, ecr:BatchCheckLayerAvailability, ecr:InitiateLayerUpload, ecr:UploadLayerPart, ecr:CompleteLayerUpload, ecr:PutImage

To pull images, CodeBuild needs `GetDownloadUrlForLayer`, `BatchGetImage`, and `BatchCheckLayerAvailability`. To push images, it needs `InitiateLayerUpload`, `UploadLayerPart`, `CompleteLayerUpload`, and `PutImage`. These permissions cover the full lifecycle of pulling and pushing Docker images to and from ECR.

Why the other options are wrong

  • A. These are CodeBuild service permissions, for controlling CodeBuild itself, not for interacting with ECR.
  • B. These are S3 permissions, which are unrelated to ECR image operations.
  • D. These permissions are for describing and listing ECR resources and getting an authorization token, but they do not permit the actual pulling of image layers or pushing of new images.

CodeBuild ECR Permissions

The specific IAM permissions required by the AWS CodeBuild service role to pull Docker images from and push Docker images to Amazon Elastic Container Registry (ECR).

  • Pulling requires layer/image retrieval.
  • Pushing requires layer upload/image put.
  • Permissions must be granted to CodeBuild's service role.

Memory trick: ECR-BUILD: Every Container Requires Building, Uploading, Imaging, Downloading.

More Deployment questions